SC-200 Manage a security operations environment Practice Question
Which TWO actions are valid ways to integrate on-premises firewall logs into Microsoft Sentinel for analysis?
⚠ Common exam trap
Watch out — candidates often confuse the Azure Activity log connector (which only covers Azure resource operations) with a general-purpose log ingestion method, or they mistakenly think the Office 365 connector can handle any external log source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the firewall to send Common Event Format (CEF) logs to a syslog server running Azure Monitor Agent.
On-premises firewall logs can be forwarded in Common Event Format (CEF) over syslog to a server running the Azure Monitor Agent (AMA), which then ingests them into Microsoft Sentinel. CEF is a standard log format supported by many security appliances, and the AMA replaces the older Log Analytics Agent for this purpose. This setup allows Sentinel to parse and analyze the firewall events for security monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the Office 365 connector.
Why it's wrong here
The Office 365 connector ingests Microsoft 365 audit and activity data—such as Exchange Online mail flow, Teams, and SharePoint events—through the Office 365 Management Activity API. It cannot receive or parse event streams from an on-premises firewall because it is a SaaS-specific data source bound to Microsoft 365 tenants. Therefore, enabling it does not satisfy the requirement to integrate on-premises firewall logs.
- ✓
Configure the firewall to send Common Event Format (CEF) logs to a syslog server running Azure Monitor Agent.
Why this is correct
This is a standard, supported integration path for firewall appliances that emit Common Event Format (CEF) messages over syslog. The firewall sends CEF to a log collector/forwarder that has the Azure Monitor Agent installed; AMA forwards the events to a Log Analytics workspace using a data collection rule, populating the CommonSecurityLog table in Microsoft Sentinel. This method preserves normalized fields such as source/destination IP, port, and action, making it directly usable by analytics rules.
- ✗
Install the Windows DNS Server connector.
Why it's wrong here
The Windows DNS Server connector is part of Sentinel's DNS solution and ingests Windows DNS analytic/event logs (e.g., event IDs 256, 257) from domain controllers, not firewall logs. It expects DNS audit data and uses the Windows DNS Server table; it does not have a syslog/CEF input and cannot capture network allow/deny firewall traffic. Installing it would only give DNS query/response visibility, leaving the firewall logs uncollected.
- ✗
Connect the Azure Activity log connector.
Why it's wrong here
The Azure Activity log connector (legacy or diagnostic settings pipeline) brings in subscription-level control-plane events from Azure Resource Manager, such as virtual machine state changes, role assignments, and resource deployments. It monitors Azure platform activity, not on-premises network perimeter traffic, and contains no fields for raw firewall allow/deny sessions. Connecting it cannot replace a syslog/CEF or custom-log ingestion path for on-premises firewall data.
- ✓
Use the Microsoft Sentinel Data Collector API to send custom logs.
Why this is correct
The Microsoft Sentinel Data Collector API is a REST endpoint that accepts custom JSON arrays and inserts them into a custom Log Analytics table, making it valid for on-premises firewall logs in formats that CEF cannot represent or when no agent-based collector is feasible. You authenticate with an Microsoft Entra ID application that has the Log Analytics Contributor role, and you POST records to the workspace ID's endpoint. This approach requires a custom forwarding script or application but gives full flexibility over field mapping.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.